Hacker Newsnew | past | comments | ask | show | jobs | submit | duffn's commentslogin

I've previously had somebody from Microsoft reach out to me directly about their entries and had somebody from RedHat create an issue, but I don't think either actually took action.

I'll continue to try though and am evaluate ways that the site can actually help companies update their rules.


I'm glad you enjoy it! If you have any sites you like to add, please feel free to contribute. https://github.com/duffn/dumb-password-rules/blob/main/CONTR...


Thanks for the feedback, the gallery seems to be not well loved, so will be re-evaluated.


Maybe two views? I sort of liked the gallery tbh.


Good feedback, thanks! Pagination through items would be a great addition and the gallery seems to be not loved, so will be re-evaluated.


Good idea! I've added an issue for discussion here: https://github.com/duffn/dumb-password-rules/issues/445


Please open an issue to discuss any improvements you'd like to see!


Hi, I made this.

It seems like most of you are as enraged as I am about some of these password rules. They just flat out make me mad.

It's not much, but I've actually had one company reach out to me after making it on the list and they made their password rules less dumb.

So, if you find any particularly egregious offenders, do your part and submit a PR. It may actually make a difference.


> I've actually had one company reach out to me after making it on the list and they made their password rules less dumb.

That’s a huge win!

My pet peeve is sites that block pasting, say, from a password manager (glaring at you, Costco signup page). Those sites don’t usually include “do not paste” in the listed requirements, so this doesn’t really work with your screenshot approach. Ideas?


> My pet peeve is sites that block pasting

Firefox: about:config: dom.event.clipboardevents.enabled, toggle to "false" (default is true).

Result: websites can no longer block you from pasting things into form fields on your own browser on your own computer.


There is a Firefox extension called Don’t Fuck With Paste which let’s you toggle this per-website with a button.


In what situation would you want this enabled?


When a website is fucking with your ability to copy or paste!


I used to set this permanently, but discovered if you use facebook making status updates and comments become broken due to how fb seems to scan your input to apply styling.

But I often have to toggle it off temporarily to bypass the stupid copy/paste blocks.


You can create a bookmarklet to disable paste event listeners.


note for firefox users, that this will break copy/paste in google docs


I tried this, but this breaks some web apps where I need clipboardevents to work (e.g. Google Docs). There needs to be a more granular option for this somehow, possibly in a plugin.


Then you'll discover sites that consume your password by Javascript in the onKeyPressed event handler.


so you can paste with the menu? Because I guess they would just catch the keyboard events?


I think they must block catching Ctrl+C/V/X, because those key combos work for me with that flag.


Nope. Don’t think so.


Dunno about educating all those idiots, but for mitigating their idiocy I have a two-line AutoHotKey script (this is in Windows) called FakePaste mapped to ctrl-shift-alt-V. All it does is read from the clipboard and pretend to type those characters, one per 100ms if I recall correctly, or maybe I set it to 200ms. AHK can mimic keypresses at the system level, so it defeats whatever silly shit anyone tries to do in the browser. It's as if you were typing. If you're on Windows and willing to install AutoHotKey I can give you the script.


I'm a big fan of this browser extension "Don't fuck with Paste" https://chrome.google.com/webstore/detail/dont-fuck-with-pas...


I've noticed a number of sites now are doing something that interferes with the password manager (Lastpass in this case). Common problems are either that autofill doesn't work (even explicitly clicking autofill does nothing), or they put a button in the username/password field that's exactly where Lastpass puts its button, so it's impossible to click.

I don't get it -- don't the sites want users to use more secure passwords? That should mean encourage password managers, unless they imagine I'm gonna remember a 32 character random unique password for every website?


I contacted my credit union about this and they responded their auditors required it for security compliance reasons. Thankfully after many months they "fixed" it by removing the restrictions... but made the login a multipage ordeal which still breaks my pw manager.


Just to add. I'm Not sure if it's just a policy thing, but when a windows rdp session locks, pasting the password is blocked. Manually typing the password becomes a pain. I really hope anything that blocks pasting in forms has good reason, an not just psuedo security


If you have a Microsoft or Logitech mouse you can map a button to a macro that types your password. It works well with rdp password fields.


> My pet peeve is sites that block pasting

Safari users can install StopTheMadness which disables this and other such nonsense.


You should have an honor roll for companies which were bad but fixed their dumb password rules.


I wish ING in Australia was as secure as your example site. Here we get a javascript number pad and a 4 digit numeric password. Hello 1998


Hi, this needs a checklist or ability to see severity of infractions because some of these edge cases are very dumb to elevate alongside the truly broken flows


Yeah, compare the very first two on there right now. The first is "can't use '%'". The next one has 7 very specific rules.


That one smacks of character encoding issues or badly sanitised inputs.


This is a good idea. I’ll think about how to handle it.


That's awesome. This is a great idea, if there's any way to get sites to fix their stupid rules, it's by shaming them :)


Amazon mails to change your password every three months. How does one come up new passwords every three months?


Using a password manager. Most include functionality to re-generate/rotate a record's password in-place, and then copy the new one to the clipboard (or even directly into the web page).

I use 1Password and even though I agree that forced password rotation is dumb, this makes it painless.


I am actually appalled and baffled at American Express not applying case sensitivity. Like, what the actual.


I literally couldn't apply for an American Express card about 15 years ago because my (ISP) email address was too long. I wonder why they chose to restrict it rather than go with the standard email max length; they had to put effort in to pointlessly restrict new signups. Odd.


Back in '99 or so, there was a company called Halibut Stuff selling T-shirts at Defcon (and presumably other events) that included a free email redirect service with purchase of a shirt.

So I got a shirt that said "myself@iwenttodefcon7.andalligotwas.thislousyemailaddress.com"

Not too much later, I ended up working in software validation, and I broke so many login forms with that perfectly-valid address, I lost count.

Since then, Halibut Stuff dissolved and the forwarding service is long gone. If some HN reader wanted to set up a Mailinator-like service that generates absurd-yet-RFC-compliant email addresses for such testing, I think there might be a market.


Like anyone would actually use such a testing service.

Until a few years ago it was fairly commonplace for sites to reject my perfectly valid addresses just because they had more than one period (i.e., a subdomain) or in one case, ended in the .us TLD.


Likely because of integration with legacy tech.


I remember when their max password length was 8 characters. It blew my mind that a (effectively) bank had such terrible requirements. At least they fixed that


The 8-character limit was probably because the web site was just a fancy front-end to some decades-old mainframe system. You'd be surprised the age of technology and software big banks rely on. They tend not to fuck with a working system, partly because their reputation and millions or billions of dollars are on the line, but also because no manager wants to be the reason for a critical outage.


I agree. It would be fine for the vast majority of people, but I can't ever see myself actually writing code on an iPad.


I write code on my on a daily basis. Coda, Swift Playgrounds, or Coda as my ssh client into a linux server and then emacs on the server. As a lightweight LTE capable environment, it's pretty amazing. It entirely depends on what you code but for web application or iOS dev it's pretty damn capable.


A bit of a hodge-podge of books, but I always have a hard time turning down a good book deal.


According to the screen shot in the repo, it's not even case sensitive either.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: